Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 31 Jul 2008 17:35:06 +0200
From:      Tilman Linneweh <arved@arved.at>
To:        freebsd-pf@freebsd.org
Subject:   pf dropping packets despite pass all rule
Message-ID:  <20080731153506.GA61317@arved.priv.at>

next in thread | raw e-mail | index | archive | help
Hi list,

My setup:

LAN -> Router with PF <- gif tunnel with IPSEC -> Server

The router is running FreeBSD 7.0. Protocol is IPv6. ping6  works, 
but TCPv6 from LAN to Server does not work, unless i disable PF.

Excerpt from pf.conf:
pass in  quick  on gif0 all keep state
pass out quick on gif0 all keep state

pflog0 contains some strange packets:
http://arved.priv.at/~arved/strangepackets.pcap

IPSEC_FILTERTUNNEL does not make a difference.

I don't understand why pf is dropping something on gif0. And i can't decode
what kind of packets these are, and why they are necessary for TCPv6.

Any ideas?

regards
arved



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20080731153506.GA61317>